noun
When you use the field extractor to create custom fields, you can specify required text to improve the accuracy of the field extraction. The regular expression created for this extraction ensures that field values are extracted only from events that contain the required text string.
For example, if you use the field extractor to create a field extraction for candidate_name
and candidate_id
fields with the required text "Department H," then Splunk Enterprise extracts only candidate_name
and candidate_id
values from fields that contain the string "Department H."
In the Knowledge Manager Manual: